{"id":"CVE-2025-0395","details":"When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.","modified":"2026-08-15T04:07:15.942114359Z","published":"2025-01-22T13:11:30.406Z","related":["ALSA-2025:3828","ALSA-2025:4244","CGA-hc6g-7jqg-qmgg","SUSE-SU-2025:0510-1","SUSE-SU-2025:0562-1","SUSE-SU-2025:0582-1","SUSE-SU-2025:20135-1","SUSE-SU-2025:20236-1","SUSE-SU-2026:20178-1","SUSE-SU-2026:20198-1","SUSE-SU-2026:20563-1","openSUSE-SU-2025:14851-1","openSUSE-SU-2026:20133-1"],"database_specific":{"cna_assigner":"glibc","cwe_ids":["CWE-131"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/0xxx/CVE-2025-0395.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/01/22/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/01/23/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/04/13/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/04/24/7"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-398330.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-577017.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00039.html"},{"type":"WEB","url":"https://sourceware.org/pipermail/libc-announce/2025/000044.html"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2025/01/22/4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/0xxx/CVE-2025-0395.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0395"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250228-0006/"},{"type":"ADVISORY","url":"https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001"},{"type":"REPORT","url":"https://sourceware.org/bugzilla/show_bug.cgi?id=32582"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://sourceware.org/git/glibc.git","events":[{"introduced":"6392473fe970b0cdace62f31000a83ba0fcf6161"},{"last_affected":"3d1aed874918c466a4477af1da35983ab036690e"}],"database_specific":{"extracted_events":[{"introduced":"2.13"},{"last_affected":"2.40"}],"source":"AFFECTED_FIELD"}}],"versions":["glibc-2.40","glibc-2.39.9000","glibc-2.39","glibc-2.38","glibc-2.38.9000","glibc-2.37","glibc-2.37.9000","glibc-2.36","glibc-2.36.9000","glibc-2.35","glibc-2.35.9000","glibc-2.34","glibc-2.34.9000","glibc-2.33","glibc-2.33.9000","glibc-2.32","glibc-2.32.9000","glibc-2.31","glibc-2.31.9000","changelog-ends-here","glibc-2.30","glibc-2.30.9000","glibc-2.29","glibc-2.29.9000","glibc-2.28","glibc-2.28.9000","glibc-2.27","glibc-2.27.9000","glibc-2.26","glibc-2.26.9000","glibc-2.25","glibc-2.25.90","glibc-2.24","glibc-2.24.90","glibc-2.23","glibc-2.23.90","glibc-2.22","glibc-2.22.90","glibc-2.21","glibc-2.21.90","glibc-2.20","glibc-2.20.90","glibc-2.19","glibc-2.19.90","glibc-2.18","glibc-2.18.90","glibc-2.17","glibc-2.17.90","glibc-2.16.0","glibc-2.16.90","glibc-2.16-ports-merge","glibc-2.16","glibc-2.16-tps","glibc-2.15","glibc-2.14.9000","glibc-2.14","glibc-2.13"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0395.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}